Highlighted wordsare glossary terms — tap one for a plain-language definition.
Protecting your accounts is about how you prove who you are. This lesson is about everything that surrounds that: recovery details, saved sessions, old devices, connected apps, and dormant accounts. A login can be strong while the recovery process is weak — and attackers know it.
Strong locks need a safe spare key
Strong security should not accidentally leave the legitimate account owner permanently locked out. Recovery codes are emergency spare keys: store them somewhere secure that you could still reach if your primary device were unavailable. There's no single right place for everyone — a Password managerWhat it means: Software that generates, stores, and fills unique account passwords, and may also manage passkeys or other credentials.Example: The manager generating and filling a 20-character password you never have to recall.What to do: Set one up and move your email, banking, and cloud passwords into it first.Important: Protect it with one strong passphrase plus MFA, and never share that passphrase.What does this mean?, a printed copy in a safe, or a locked drawer can all work, as long as it isn't inside the account they unlock.
- Ask yourself: is my recovery phone number still correct, and is my recovery email still accessible?
- Is that recovery email itself protected with a unique credential and strong Multifactor authenticationWhat it means: Using more than one type of authentication evidence before an account grants access.Example: Entering your password and then approving the login through an authenticator app.What to do: Turn it on first for your email, financial, social-media, and cloud accounts.Important: Never give an unexpected login code to someone who contacts you.What does this mean??
- Did this service give me BackupWhat it means: An additional copy of information that can be restored if the original is lost, damaged, or encrypted.Example: An external drive copy plus a cloud copy of your photos.What to do: Keep one copy disconnected, and test restoring a single file so you know it works.Important: Ransomware encrypts backups that stay permanently connected.What does this mean? or recovery codes — and do I know where they are?
- What happens if I lose my phone? Register a second method, or a backup Security keyWhat it means: A physical FIDO-compatible device used to provide strong, phishing-resistant authentication.Example: A small USB or tap-to-approve key you use when signing in.What to do: Register two keys: one for daily use and one kept in a safe place.Important: Among the strongest practical options — no method makes an account impossible to compromise.What does this mean?, before you need it.
Sessions, devices, and connected apps
Most services keep a list of everywhere you're currently signed in, plus every app you once granted access. Old laptops, borrowed tablets, and forgotten third-party tools stay logged in long after you've moved on.
- Review active sessions and sign out anything you don't recognize.
- Remove devices you no longer own or use.
- Revoke third-party apps and permissions you no longer need.
- Check for unfamiliar activity — new logins, new locations, changed settings.
Close the side doors
A few quiet settings can hand over your account without touching your password. Email forwarding rules can copy your mail elsewhere. A phone number taken over in a SIM swapWhat it means: An attack in which a criminal tries to take control of your phone number, which can affect text-message codes and account recovery.Example: Your phone loses service, and password reset texts start arriving somewhere else.What to do: Ask your mobile carrier to add a PIN or port-out lock to your account.Important: It's one reason phishing-resistant sign-in is preferable to SMS where a service offers both.What does this mean? can intercept text codes and recovery calls. Dormant accounts you've forgotten can still be taken over and used against you.
- Check your email account for forwarding rules and filters you didn't create.
- Ask your mobile carrier to add a PIN or port-out lock to your number.
- Delete accounts you no longer use, especially ones tied to your main email.
- Where a service offers phishing-resistant sign-in, it also reduces how much rides on your phone number.
Why Hygi. recommends this — the guidance above follows these published sources:
NIST
SP 800-63B-4: Digital Identity Guidelines — Authentication and Authenticator Management (July 2025)(opens in a new tab)Account recovery and re-binding authenticators as part of the authentication lifecycle.
CISA
Project Upskill — securing accounts and devices for high-risk individuals(opens in a new tab)Sessions, connected apps, SIM-swap risk and recovery hardening.
Brought to you by NorthBridge
Unfamiliar term? Open the Digital Safety Glossary